
Social Login by BestWebSoft Security & Risk Analysis
wordpress.org/plugins/social-login-bwsAdd social media login, registration, and commenting to your WordPress website.
Is Social Login by BestWebSoft Safe to Use in 2026?
Generally Safe
Score 100/100Social Login by BestWebSoft has a strong security track record. Known vulnerabilities have been patched promptly.
The social-login-bws plugin exhibits a generally strong security posture, with a high percentage of properly escaped outputs and a robust implementation of nonce and capability checks across its identified entry points. The absence of unpatched CVEs and the presence of only one medium severity vulnerability in its history, which is also patched, are positive indicators. Furthermore, the fact that all four AJAX handlers have authentication checks significantly reduces the risk of unauthorized actions through these endpoints.
However, the presence of the `unserialize` function poses a notable risk. If this function is used with unsanitized user-supplied input, it can lead to remote code execution vulnerabilities. While the taint analysis did not reveal critical or high severity flows, the potential for such issues with `unserialize` should not be overlooked. The plugin also makes several external HTTP requests, which could be a vector for various attacks if not handled securely, although the analysis doesn't specifically highlight any unsanitized external requests.
Overall, the plugin is well-protected against common web vulnerabilities with good coding practices in place. The main area of concern lies with the `unserialize` function, which, despite not currently showing exploitable taint flows, represents a latent risk. The historical vulnerability pattern suggests the developer has addressed past issues promptly, which is a positive sign for future maintenance.
Key Concerns
- Dangerous function: unserialize used
- 50% of SQL queries not using prepared statements
- 4 flows with unsanitized paths (taint analysis)
- Bundled library: Guzzle (potential for outdated versions)
Social Login by BestWebSoft Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Social Login by BestWebSoft <= 0.1 - Multiple Cross-Site Scripting
Social Login by BestWebSoft Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Login by BestWebSoft Attack Surface
AJAX Handlers 4
WordPress Hooks 44
Maintenance & Trust
Social Login by BestWebSoft Maintenance & Trust
Maintenance Signals
Community Trust
Social Login by BestWebSoft Alternatives
UsersWP – Social Login
userswp-social-login
Social Login addon for UsersWP.
Happy Social Login
happy-social-login
Enables user authentication through various social media accounts. Login through Google, Facebook, LinkedIn, GitHub and more.
Rundiz OAuth
okv-oauth
Use OAuth such as Google, LINE to login and register.
Wapu Auth – Google Social Login for WordPress & WooCommerce
wapu-auth-social-login
Google Social Login for WordPress & WooCommerce -- free. Let users register and login with their Google account in one click. No passwords, no forms.
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.
Social Login by BestWebSoft Developer Profile
32 plugins · 17K total installs
How We Detect Social Login by BestWebSoft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-login-bws/assets/css/social-login-bws.css/wp-content/plugins/social-login-bws/assets/js/social-login-bws.js/wp-content/plugins/social-login-bws/assets/js/social-login-bws.jssocial-login-bws/assets/css/social-login-bws.css?ver=social-login-bws/assets/js/social-login-bws.js?ver=HTML / DOM Fingerprints
bws-social-login© Copyright 2021 BestWebSoft ( https://support.bestwebsoft.com )This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+17 moredata-button-colordata-button-sizedata-button-shapedata-button-textscllgn_options[social_login]